AI literacy: Data, privacy and internal policy when using generative AI
Three months ago, an admin at a Madrid consultancy pasted a client contract into ChatGPT to help extract clauses. Dumped the whole thing. Names, amounts, expiry dates, contact emails. The next day, the client rang furious: someone had sent a competing offer to his email address.
It wasn't a leak. ChatGPT hallucinated: invented an email similar to the client's real one, used it in its own response, and the admin copied it without checking. But here's the real breach: OpenAI kept that entire contract for 30 days. If he'd been using ChatGPT free, it would have stayed on their servers indefinitely.
That's 80% of data loss in a modern SME. Not an attack. Copy and paste.
How each platform handles what you upload
What happens to your data depends almost entirely on which plan you're using. Not marketing. Actual legal terms.
| Platform | Plan | Retention | Used for training | Contract | Best for |
|---|---|---|---|---|---|
| OpenAI | ChatGPT Free | Indefinite (your account) | Yes, manual opt-out | Generic terms of service | Prototypes without real data |
| OpenAI | ChatGPT Plus | 30 days | Yes, manual opt-out | Generic terms of service | Personal use with non-sensitive data |
| OpenAI | ChatGPT Business | 90 days (configurable) | No | Data Processing Addendum (DPA) | SMEs with some internal data |
| OpenAI | ChatGPT Team | 90 days (configurable) | No | DPA | Teams with repeatable workflows |
| OpenAI | ChatGPT Enterprise | Configurable, min. 90 days | No | DPA + custom contracts | Companies with sensitive or regulated data |
| Anthropic | Claude Free | 30 days after deletion | Yes, opt-out in settings | Generic terms | Prototypes |
| Anthropic | Claude Pro | 30 days after deletion | Yes, opt-out in settings | Generic terms | Personal use |
| Anthropic | Claude for Work | 30 days maximum | No | Specific commercial contract | Small teams |
| Anthropic | Claude Enterprise | Per contract | No | Custom contract | Large companies |
| Gemini Free | Indefinite in your account | Yes, by default | Generic terms | Prototypes without data | |
| Gemini Business | 90 days | No (if CCPA/GDPR active) | Business DPA | SMEs with Google Workspace | |
| Gemini for Workspace | 90 days | No | Workspace DPA | Companies with Google integration |
What you see in the table comes from reading the actual 2026 terms of service. Three critical nuances:
First: "retention" is not the same as "actually deleted". When OpenAI says "30 days", it means your inputs disappear from active training systems after 30 days. But backup servers may keep copies longer. In practice, if there's a legal investigation, they're stored longer.
Second: opt-out in Claude means you go to your account, hit Settings > Privacy > "Improve Claude for everyone" and turn it off. It's on by default. This was documented in June 2026 when Anthropic updated its policy: unless you do it manually, your conversations train the model.
Third: a DPA (Data Processing Addendum) is not a "guarantee". It's a legal document saying that OpenAI, Anthropic or Google act as "data processor" on your behalf, not as owner. It means you have legal rights if something fails. It doesn't mean your data is bulletproof.
Retention, training and enterprise-level contracts
This is where security becomes actual policy.
Free plans
ChatGPT Free, Claude Free, Gemini Free: you have no contract. You're the product. Your conversations are saved in your account, but can be used to train future models. OpenAI states it explicitly: "By default, conversations in ChatGPT and content in the Playgrounds can be used to train our models". Claude is the same. Google too.
Does it mean they read your conversations? Not directly. An algorithm extracts patterns, identifies behaviours, learns from your input. No human reading. But the machine does.
Case study: you work at a startup using ChatGPT Free for copywriting. You pasted a real email to a client explaining your market entry price: €1.2 million. ChatGPT learned from that. A competitor uses ChatGPT Pro weeks later, asks "pricing systems for SaaS startups", and Claude gives variations that match your strategy exactly. Coincidence? Statistically, no.
Individual paid plans
ChatGPT Plus (€10/month), Claude Pro ($20/month), Gemini Premium: you have a consumer subscription. By default, your conversations still train the model. But with a caveat: "Business conversations are not used for training" on Plus. Which means OpenAI tries to detect if you're in "business mode" and wouldn't train on that context. But it's a heuristic, not a guarantee.
Main benefit: 30 days maximum retention on OpenAI servers, then deleted. Not indefinite.
Case study: you're a freelancer using Claude Pro. You draft a proposal for a client including their company data. Claude won't formally train on that because you've already paid. But if your session gets flagged for security (detects sensitive data), Anthropic reserves the right to retain and review.
Team and enterprise plans
Everything changes. ChatGPT Business (min. 2 users, $30/user/month), ChatGPT Team (min. 2 users, $30/user/month), Claude for Work, Gemini for Workspace: you get a Data Processing Addendum. It means:
- Your inputs are NOT used to train public models.
- Servers are physically separate (in some cases).
- There's legal audit: if something fails, you have grounds for claim.
- You can set retention policies (90 days minimum at OpenAI, configurable after).
Example: you're at an agency with 8 people using ChatGPT Team. You upload a confidential client brief. Data is not used for training. It's retained 90 days in your company workspace, then deleted. If AEPD audits, OpenAI must prove compliance.
ChatGPT Enterprise is the top tier. No user limit. You can:
- Set custom retention (could be 180 days, 1 year, more).
- Add Enterprise Key Management (your company manages encryption keys).
- HIPAA, GDPR, SOC 2 Type 2 certified.
- Conversations completely isolated from everyone else.
Cost: negotiate directly with OpenAI. It's above €300-500/user/month. Which means if a 20-person SME takes it, that's €150,000/year minimum.
What you never upload
Some things never go in any chatbot, regardless of plan.
GDPR special categories
According to AEPD (which opened an investigation against OpenAI in 2025): don't upload special category data. It means:
- Biometric data (face photos for training).
- Medical history.
- Data of minors.
- Sexual orientation, religion, ethnic origin.
- Criminal records.
The reason: even with a DPA, the legal risk is disproportionate. If it leaks, civil and administrative liability for the company.
Trade secrets
Don't upload:
- Proprietary formulas or processes.
- Source code with known vulnerabilities.
- Exact pricing strategy.
- Names of major clients.
- Non-public contracts with unique clauses.
AEPD case (May 2025): a solicitor uploaded a complete client contract to ChatGPT to automate analysis. The contract contained the client's trade secrets (profit margin, unique suppliers). No technical leak. But if a competitor had asked ChatGPT about "similar contracts", the machine could have hallucinated information which, though invented, was based on patterns from the leaked document.
Non-public third-party information
Don't upload:
- Customer data without explicit consent.
- Private employee communications.
- Photos of people without permission.
AEPD is clear: "Images of third parties should not be sent to generate content, as it could constitute a breach or even a crime".
What you can upload with care
Not everything is prohibited. But it requires caution.
Anonymised internal data
You can upload your company data if you anonymise it first. It means removing direct identifiers:
Wrong: "Telefónica reduced operating costs by 35% after implementing our software".
Right: "A telecommunications sector client with over 10,000 employees has reduced operating costs by 35% after implementing our software".
The change is small. Legal risk disappears. You can upload this to ChatGPT Free without issue.
Public data
You can upload published articles, public reports, CNAE data, company registry records, news. It's information already on the internet. The machine learns nothing "new" from you that it didn't already know. Zero risk.
General company data
You can upload: employee count, public revenue, products/services, location, public leadership team. It's not sensitive. Already on your website.
How to write a one-page internal AI policy
This is where most companies fail. They have a policy. But it's:
- Too long (30 pages of legal jargon).
- No concrete examples ("what's forbidden" without real examples).
- No incident process ("if something went wrong, what now?").
- Not shared ("IT has a copy, nobody else saw it").
A policy that gets read and applied fits on one page. Here it is:
GENERATIVE AI TOOL USE POLICY - [COMPANY NAME]
Version: 1.0
Effective date: 1 September 2026
Owner: Management / Compliance Lead
Next review: 1 September 2027
SCOPE
This policy applies to all employees, contractors and consultants using generative AI tools. Includes ChatGPT, Claude, Gemini, Copilot and similar. Both company-authorised versions and personal use on corporate devices.
APPROVED TOOLS
- ChatGPT Business (Marketing team).
- Claude for Work (Product team).
- Gemini for Workspace (integrated in Google Workspace, everyone).
Any other tool requires IT approval before use.
PERMITTED
- Drafting internal content (emails, drafts, scripts).
- Analysing public data (news, published reports).
- Generating ideas and brainstorming.
- Summarising anonymised internal documents.
- Translating corporate texts.
- Testing prompts and improving workflows.
PROHIBITED
- Uploading customer data. No names, emails, orders, contracts, tax IDs.
- Uploading medical, financial or biometric information. Of employees, customers or third parties.
- Uploading unreleased proprietary code containing vulnerabilities or secrets.
- Uploading photos of people without prior written consent.
- Uploading passwords, tokens, API keys or credentials.
- Using AI to access third-party data without authorisation.
- Uploading private conversations (between employees, between company and customer) without redaction.
- Using unapproved tools on corporate devices.
WHEN IN DOUBT: ANONYMISE AND REWRITE
If you want to upload something but aren't sure:
- Remove specific names. Swap "Acme Corp" for "client in the pharmaceutical sector".
- Remove exact figures. Change "€250,000 budget" to "six-figure budget".
- Remove exact dates. Change "contract ends 15/03/2027" to "contract ending Q1 2027".
After anonymising, upload away.
REQUIRED APPROVALS
To upload sensitive information (even if anonymised), get approval from your direct manager. Some examples:
- Internal financial data (margins, costs, budgets).
- Unpublished product strategy.
- Communications with major clients (even without names).
- Anything affecting competitiveness.
Cost of not asking: 5 minutes of paperwork. Cost of a leak: legal disaster.
INCIDENT PROCESS
If something goes wrong:
- Acknowledge it. Someone uploaded customer data by mistake. Notify IT within 2 hours.
- IT investigates. What was uploaded? To which tool? When? Who else saw it?
- Notify the Compliance Lead. AEPD requires reporting breaches within 72 hours if there's risk.
- Remediate. Delete the conversation (if possible), change passwords/credentials, notify the customer if needed.
- Document it. Not to blame. To prevent it tomorrow.
No punishment for reporting. There is punishment for hiding it.
REVIEW AND UPDATES
This policy is reviewed annually or when:
- A new tool is adopted.
- Legislation changes (AEPD, AI Act).
- An incident requires adjustment.
- Teams report confusion.
Owner of updates: [Name, Title, Email].
That's it. One page. Printable. Shareable. Understandable without a solicitor.
How to actually deploy a policy that gets read
Having a policy in a folder doesn't help. It needs to circulate.
Month 1: Communication.
Send an email to everyone. Not a PDF attachment nobody opens. An email with a short intro:
"We're starting to use ChatGPT in Marketing and Gemini in Google Workspace. To prevent accidental leaks of customer data, we've approved an internal policy. Read it (5 minutes), confirm you understand it (reply to this email with 'Confirmed'), and if you have questions, ask IT."
Attach the policy as a link to a shared doc (Google Docs or Notion), not as a downloadable PDF. That way everyone sees the right version, not ten outdated ones.
Month 1-2: Role-based training.
Not one two-hour generic session on "how AI works". Specific sessions:
- Marketing: how to use ChatGPT without uploading customer data. 30 minutes.
- Product: how to use Claude for feature analysis. 20 minutes.
- Finance: what NOT to upload (ever). 15 minutes.
- Support/Sales: don't copy customer tickets. 15 minutes.
Record each session. Anyone who can't attend watches the recording. Ask for confirmation they watched.
Month 3 onwards: Evidence.
Create an "AI Compliance" folder in your Drive/OneDrive. Save:
- Current version of the policy with date.
- Initial distribution email + replies confirming they read it.
- Recordings of training sessions.
- Attendance list for each session.
- Record of any incident + how it was resolved.
When AEPD or AESIA shows up, pull the folder. "Look: we have a policy, we trained, we track, we document incidents". You survive.
Common mistakes you see constantly
Mistake 1: 30-page policy
A company hires a solicitor who drafts a "Corporate AI Policy" document that reads like a merger agreement. It has sections on "European regulatory framework", "principles of responsible AI", "systemic risk governance".
Your team skims it, closes it, forgets it. Nobody follows it because nobody understands it. Inspection arrives: "Do you have an AI policy?" You say yes. You show the 30 pages. The inspector reads paragraph 3.2 on "principles" and asks: "Does each employee know what to upload and what not to?" Awkward silence.
Fix: one page. Two max. Real examples. Plain language.
Mistake 2: policy without examples
"Don't upload sensitive data". Sensitive how?
- Is a customer name sensitive? (Yes)
- Is "client in the tech sector" sensitive? (No)
- Is an email sensitive? (Yes)
- Is "customer communication" sensitive? (No, if anonymised)
A working policy says: "Wrong: upload 'Email from Acme Corp asking for 30% discount'. Right: upload 'Client in industrial sector asking for volume discount'".
Mistake 3: policy without incident process
What does someone do if they realise they just uploaded a customer contract to ChatGPT?
Option A: Hide it. Hope nothing happens. Nothing does. Three months pass. Audit arrives. It gets discovered. Disaster.
Option B: Report immediately. IT investigates in 2 hours. They know exactly what was uploaded. They delete the conversation. They change credentials if needed. It's not a problem. It's a documented anecdote.
Policy without process = option A. Policy with process = option B.
Mistake 4: no documentation
Training was real. You did a session in January 2026. Everyone saw it. But you didn't save:
- The presentation.
- Who attended.
- When.
- A record of understanding.
Inspector: "Do you have a record of AI training?" You: "Yes, we did a session in January". Inspector: "Can you show me the attendance record?" Silence. It doesn't exist.
Documentation takes 10 minutes. An attendance list. A presentation saved to Drive. Nothing else. Not doing it is operational error.
Mistake 5: translating AEPD directly
AEPD published a "decalogue" on AI in 2025. It has advice like "protect privacy", "avoid sensitive data", "comply with GDPR".
A company copy-pastes that into their policy. Result: 15 pages of vague recommendations that don't apply specifically to which tools they use. Employees read "protect privacy when using AI tools" and still don't know if they can upload anonymised customer names.
Fix: read AEPD, understand the spirit, translate it into specific policy for your company. "Don't upload customer names. Do upload 'client in sector X' without the name."
How you know your policy actually works
After three months, ask:
- Can someone quote the policy without Googling? If someone from the Marketing team says "I can't upload X because the policy says Y", it works.
- Was there an incident? If it was reported voluntarily, excellent. It means the policy got read and people understand the risks.
- Did behaviour change? Before: "I'll upload this contract to ChatGPT to summarise it". After: "I'll anonymise the contract first".
- Can the leads show evidence? IT should be able to pull the compliance folder and show policy + training + documented incidents.
If all this exists, you're covered for an audit. If something's missing, there's a gap.
Next chapter
So far we've covered how the machine works (Chapter 2), what data to protect (this one), and what policy to write.
The next chapter is role-based literacy: what a marketing lead needs to know, what a solicitor does, what an operations director should know. It's different for each. Training needs to be specific.

